Section Number and Name:
The documentation focuses around the multitenant plugin. With the network policy plugin now fully supported and being the popular choice as per the community, it is not clear if egress policies must ONLY need multitenant plugin or will they work with the network policy plugin also.
Describe the issue:
Customers are confused what the caveats are and how to pick out what is relevant if they use the network policy plugin.
Suggestions for improvement:
If lines could be added on how things would differ if the network policy plugin is used it would greatly makes things clearer.
Ravi: Does the egress firewall work with all three of our SDN plugins? Thanks.
Yes, egress network policy is compatible with all three SDN plugins. Keep in mind that networkpolicy plugin provides granular isolation (namespace or pod selector). Currently egress network policy can only be applied at the namespace level with some caveats: only one egress np for namespace allowed, namespace that share network with other namespaces are not allowed and global namespaces are not allowed.
Correction to my previous comment, I gave contradicting statement: egress np compatible with all 3 SDN plugins but global namespaces are not allowed. Subnet network plugin only has global namespaces.
So the correct answer: egress network policy is compatible with 2 SDN plugins: multitenant and networkpolicy plugins.
Thanks, Ben, Rajat
I've created a PR for this:
Most of the caveats Rajat mentions is already there in an admonition, so I extended on that with the rest of the info.
Ruchika, can I verify that the information you're requesting is in the PR? I don't think writing the docs as though network policy is the one the reader will be using, because it is not yet the default. Once that happens, then I'd agree the docs would need a rewrite.
Hmm looks like Ruchika's account has shut down. I think the information needed is there, so I'll move forward with this BZ, but if anyone watching has thoughts on the PR, please let me know.
Commit pushed to master at https://github.com/openshift/openshift-docs
Merge pull request #10421 from bfallonf/egressnetwork_1565778
Bug 1565778 Added caveats about egress policy and networkpolicy plugin
Link to released docs: